CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-16158

highCVSS 8.7covered by 1 sourcefirst seen 2026-07-18
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source pairs can therefore produce the same key while resolving to different upstream URLs. When getUpstream selects an upstream from request data, a URL cached for one upstream can be reused for a request intended for another upstream, causing cross-upstream data access and modification. The default configuration is affected. Setting disableCache to true prevents the behavior. Patches: upgrade to @fastify/reply-from 12.6.4. Workarounds: pass disableCache: true when registering the plugin.

⚡ Watch CVE-2026-16158

Get an email if CVE-2026-16158 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-16158

CVE.org record

Embed the live status

CVE-2026-16158 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-16158 status](https://www.csirts.com/badge/CVE-2026-16158)](https://www.csirts.com/cve/CVE-2026-16158)